Subira
Talk to sales Request a demo
AI-orchestrated · human-in-the-loop · evidence-first

Break it before they do.

The AI-orchestrated penetration-testing platform that doesn't just find vulnerabilities — it proves them. Hypothesis-driven agents, zero-false-positive by design, every finding backed by cryptographic evidence and mapped to PCI DSS, ISO 27001 and SOC 2.

39 specialised agents · 5 approval tiers · 15 compliance frameworks

SCAN · PENTEST / NON_INTRUSIVE LIVE
CONFIRMED SQL injection · /api/v2/accounts CVSS 9.8

oracle: positive-control + differential → REPORT lane · T1190

Illustration: agents fan out from a target along a penetration task graph; edges light as hypotheses resolve, settling on one oracle-confirmed finding.
Maps findings to
ISO 27001PCI DSS v4SOC 2NIST CSFNIST 800-53DORANIS2CIS v8

The problem

The false-positive tax, then the compliance re-typing tax.

Scanners hand security teams thousands of unproven findings. Triage becomes the job: someone has to reproduce each one by hand before anyone will fix it, and most of them were never real.

Then the second tax lands. Regulated teams re-translate those same results, by hand, into control evidence for every framework an auditor asks about — a spreadsheet exercise repeated each quarter, for every engagement.

Subira treats both as engineering problems: an oracle that refuses to report what it can't prove, and reports that come out already mapped.

How it works

Scan. Prove. Report.

01 / ORCHESTRATE

A scan fans out to specialised agents

39 agents are scheduled along a Penetration Task Graph — web, API, GraphQL, auth, infra, AD, CI/CD, mobile, wireless, cloud posture. A five-phase WebSocket monitor shows the run as it happens.

02 / PROVE

Two lanes, and only one of them ships

Every candidate faces a positive-control plus differential oracle and lands as CONFIRMED, UNCONFIRMED or INCONCLUSIVE. Only OOB-proven or CONFIRMED findings enter the report lane.

REPORT lane · proven
Leads · discarded, never reported
03 / REPORT

Evidence packaged the way auditors ask for it

Each finding carries CVSS 4.0, MITRE ATT&CK and its kill-chain. One click produces a per-framework DOCX — ISO 27001, PCI DSS, SOC 2 and the rest — plus a ZIP audit package with findings, evidence and a timestamp manifest.

Hybrid by design, not by limitation

Authorization, rules of engagement and anything irreversible stay human. Tier 3 and above require a signed cryptographic authorization token (EAT) plus human approval before an exploitation agent runs — and proof-of-concept payloads only, never destructive ones.

TIER 1Auto-run · passive discovery
TIER 2Auto-run · in-scope active testing
TIER 3EAT + single approval
TIER 4EAT + dual approval
TIER 5EAT + executive approval

Platform

One fleet, the whole attack surface.

Web through Active Directory through cloud posture, in a single platform — with a two-phase scan model that makes it structurally impossible for an assessment to run an exploitation agent.

Web & API

Crawl, fuzz and probe endpoints with per-parameter hypotheses.

GraphQL & OAuth

Introspection abuse, batching, flow and redirect-URI weaknesses.

Auth & session

Token handling, fixation, privilege boundaries and access control.

Injection, XSS, desync

SQL and command injection, reflected/stored XSS, HTTP request desync.

Deserialization & SSRF

Unsafe object graphs and server-side request forgery, OOB-confirmed.

Infrastructure

Service exposure, misconfiguration and known-vulnerable versions.

AD · Kerberos · ADCS ENUM-ONLY

Certificate-template and delegation review by enumeration, no abuse.

CI/CD

Pipeline permissions, secret exposure and build-step injection.

Mobile

MASVS-aligned checks on storage, transport and platform interaction.

Wireless

Authentication and segmentation weaknesses on in-scope networks.

Network devices

Edge and management-plane configuration on routers and firewalls.

Cloud posture WHEN CONFIGURED

Identity, storage and exposure posture once cloud credentials are supplied.

HAIE — hypothesis engine

Attack intelligence driven by hypotheses: an explore budget, UCB scoring, chain-severity reasoning and adversarial survival checks decide what is worth attempting next.

Coordination brain

Cross-scan memory with warm-start and expected-value priors, deduplication and novelty scoring, and a portfolio scheduler — so agents in a scan behave as one collective.

Threat-intel corpus

NVD, CISA KEV, FIRST EPSS and Exploit-DB, ingested live — 2,471 rows today, 1,631 of them KEV. Prioritisation stays scope- and EAT-gated.

The proof discipline

Every finding arrives already proven.

This is the standard shape of a Subira finding. Expand it to see what a report-lane result carries by the time it reaches you.

Kill chain

  1. 01Enumerated search parameter accepting unsanitised operators
  2. 02Positive control injected on a known-safe column — baseline captured
  3. 03Differential response confirmed boolean-blind behaviour
  4. 04Out-of-band DNS callback fired from the database host
  5. 05Safe proof-of-concept only — no data extracted, no writes attempted

Out-of-band evidence

DNS A · 7f3c9e.oob.subira.io
src 203.0.113.44 · db-prod-02
Δt 412ms · correlation OK

CVSS 4.0 vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

MITRE ATT&CK

T1190 — Exploit Public-Facing Application

Mapped controls

NIST 800-53 SI-10 CIS v8 16.11 PCI DSS v4 6.2.4 ISO 27001 A.8.28 CWE-89

Evidence chain

sha256 4f9a1c…8b02d7
RFC-3161 timestamp · 2026-05-14T09:22:41Z (when a TSA is configured)

LEAD · DISCARDED

Possible reflected XSS · /search?q=

Differential test showed no behavioural change; positive control failed to reproduce. Marked UNCONFIRMED and kept out of the report — a human never has to triage it.

REPORT LANE · CONFIRMED

Precision 1.00 on the confirmed bar

Zero false positives is a tested invariant, not a promise: the evaluation harness enforces precision 1.00 on everything that clears the CONFIRMED bar.

100%

Recall on the live recall-floor benchmark — XSS and SQLi, both oracle-confirmed.

Footnote: only the reflective lab was reachable in this run, so the denominator is 2.

1,964+

Automated tests, coverage-gated in CI — with 0 WCAG (axe) violations across the product.

Live

Authorization-safe on a live bug-bounty target: the rules-of-engagement flow ran end to end and out-of-scope activity was refused.

Compliance

Findings mapped to 15 frameworks, before you open the file.

Subira is designed for and mappable to the frameworks auditors actually ask about. Compliance is framed as mapping and posture — the concrete, shipped proof is a per-framework DOCX generated straight from a scan.

ISO 27002
PCI DSS v4
SOC 2
NIST CSF
DORA
NIST 800-53
ISO 27002
NIS2
GDPR Art. 32
CIS v8
OWASP Top 10
OWASP ASVS
OWASP MASVS
OWASP API Top 10
CWE/SANS Top 25

Coverage indicates mapped control density, not certification.

See a real compliance-mapped report

A redacted DOCX generated by a live scan — findings, control mapping, kill-chain evidence and the timestamp manifest, exactly as it comes out of the product.

Request the sample report

Who it's for

Built for the people who have to prove it.

PRIMARY

Banks & regulated enterprises

Testing evidence that arrives as regulator-shaped output. Surface: per-framework compliance DOCX.

In-house security & AppSec teams

Continuous, proven coverage without a triage backlog. Surface: CI/CD gates, RBAC, retest lifecycle.

Bug-bounty researchers

Stay inside the rules while you hunt. Surface: HackerOne program browse with rules-of-engagement attestation.

Red-team & CTF practitioners

Practice surfaces with the same proof discipline. Surface: Red Team and CTF workspaces, HTB bootstrap.

Deployment

Run it where your data has to stay.

Self-hosted or Subira-hosted, designed for in-region data residency. Model access, notification routing, cloud scanning and RFC-3161 timestamping activate when you configure the corresponding credential — and the platform runs deterministically without them, never fabricating a result.

Air-gapped and Helm packaging, MSSP white-label, and a public SDK/CLI are on the roadmap — coming soon, not shipped.

RBAC, OWNER → VIEWER

Custom roles, API keys and service accounts.

Immutable audit log

Finding lifecycle as a state machine, with delta detection.

Scope & EAT authorization

No agent acts outside an authorised scope — leads never bypass the gate.

Retention & erasure

Configurable retention, SIEM export, SAML SP with SSO group mapping.

The name

صبيرة — Subira

Patience. Perseverance. Proving something takes longer than guessing at it — which is exactly the discipline we chose to build into the product. Subira is built for the institutions that have to answer to a regulator, wherever they operate.

Request a demo

See it prove a vulnerability on your own scope.

A 30-minute walkthrough: a live scan, the oracle rejecting a lead, and the compliance-mapped DOCX coming out the other end.

We reply within one business day. Your details are used only to contact you — see the privacy policy.

RECEIVED

Thanks — we'll be in touch within one business day.

If it's urgent, mail sales@subira.io and mention this request.

Enter a work email address so we can reply.
No CAPTCHA. No third-party trackers on this form.